Heroku-20 and Heroku-22 stack images updated
Change effective on 11 October 2023
We have updated the heroku-20 and heroku-22 stack images to pick up
security fixes in upstream packages.
This includes fixes for the curl/libcurl CVEs announced today, including CVE-2023-38545 and CVE-2023-38546.
The new stack images will be rolled out automatically to the Common Runtime over the next 24 hours, followed by Private Spaces.
If you are using Heroku’s default buildpack-powered build system/stacks you do not need to redeploy your app to pick up these changes, since your application’s slug is applied on top of the most recent stack image each time a dyno starts. Currently running dynos will be automatically restarted, so there is no need to manually restart your app.
If your app instead uses Heroku’s container stack (most apps do not),
you will need to rebuild your app’s Docker image in order to pick up any updates in the base image
specified in your Dockerfile.
See this Dev Center article for an overview of the packages available in each stack image.
Changelog of packages
Stack: heroku-20
- Updated curlfrom version7.68.0-1ubuntu2.19to7.68.0-1ubuntu2.20
- Updated libc-binfrom version2.31-0ubuntu9.9to2.31-0ubuntu9.12
- Updated libc-dev-binfrom version2.31-0ubuntu9.9to2.31-0ubuntu9.12
- Updated libc6from version2.31-0ubuntu9.9to2.31-0ubuntu9.12
- Updated libc6-devfrom version2.31-0ubuntu9.9to2.31-0ubuntu9.12
- Updated libcurl3-gnutlsfrom version7.68.0-1ubuntu2.19to7.68.0-1ubuntu2.20
- Updated libcurl4from version7.68.0-1ubuntu2.19to7.68.0-1ubuntu2.20
- Updated libtiff5from version4.1.0+git191117-2ubuntu0.20.04.9to4.1.0+git191117-2ubuntu0.20.04.10
- Updated libvpx6from version1.8.2-1build1to1.8.2-1ubuntu0.2
- Updated libx11-6from version2:1.6.9-2ubuntu1.5to2:1.6.9-2ubuntu1.6
- Updated libx11-datafrom version2:1.6.9-2ubuntu1.5to2:1.6.9-2ubuntu1.6
- Updated libxpm4from version1:3.5.12-1ubuntu0.20.04.1to1:3.5.12-1ubuntu0.20.04.2
- Updated linux-libc-devfrom version5.4.0-163.180to5.4.0-164.181
- Updated localesfrom version2.31-0ubuntu9.9to2.31-0ubuntu9.12
Updates to packages available at build time only
- Updated libc6-i386from version2.31-0ubuntu9.9to2.31-0ubuntu9.12
- Updated libcurl4-openssl-devfrom version7.68.0-1ubuntu2.19to7.68.0-1ubuntu2.20
- Updated libtiff-devfrom version4.1.0+git191117-2ubuntu0.20.04.9to4.1.0+git191117-2ubuntu0.20.04.10
- Updated libtiffxx5from version4.1.0+git191117-2ubuntu0.20.04.9to4.1.0+git191117-2ubuntu0.20.04.10
- Updated libvpx-devfrom version1.8.2-1build1to1.8.2-1ubuntu0.2
- Updated libx11-devfrom version2:1.6.9-2ubuntu1.5to2:1.6.9-2ubuntu1.6
- Updated libxpm-devfrom version1:3.5.12-1ubuntu0.20.04.1to1:3.5.12-1ubuntu0.20.04.2
Stack: heroku-22
- Updated curlfrom version7.81.0-1ubuntu1.13to7.81.0-1ubuntu1.14
- Updated libc-binfrom version2.35-0ubuntu3.3to2.35-0ubuntu3.4
- Updated libc-dev-binfrom version2.35-0ubuntu3.3to2.35-0ubuntu3.4
- Updated libc6from version2.35-0ubuntu3.3to2.35-0ubuntu3.4
- Updated libc6-devfrom version2.35-0ubuntu3.3to2.35-0ubuntu3.4
- Updated libcurl3-gnutlsfrom version7.81.0-1ubuntu1.13to7.81.0-1ubuntu1.14
- Updated libcurl4from version7.81.0-1ubuntu1.13to7.81.0-1ubuntu1.14
- Updated libtiff5from version4.3.0-6ubuntu0.5to4.3.0-6ubuntu0.6
- Updated libvpx7from version1.11.0-2ubuntu2to1.11.0-2ubuntu2.2
- Updated libx11-6from version2:1.7.5-1ubuntu0.2to2:1.7.5-1ubuntu0.3
- Updated libx11-datafrom version2:1.7.5-1ubuntu0.2to2:1.7.5-1ubuntu0.3
- Updated libxpm4from version1:3.5.12-1ubuntu0.22.04.1to1:3.5.12-1ubuntu0.22.04.2
- Updated linux-libc-devfrom version5.15.0-84.93to5.15.0-86.96
- Updated localesfrom version2.35-0ubuntu3.3to2.35-0ubuntu3.4
Updates to packages available at build time only
- Updated libcurl4-openssl-devfrom version7.81.0-1ubuntu1.13to7.81.0-1ubuntu1.14
- Updated libtiff-devfrom version4.3.0-6ubuntu0.5to4.3.0-6ubuntu0.6
- Updated libtiffxx5from version4.3.0-6ubuntu0.5to4.3.0-6ubuntu0.6
- Updated libvpx-devfrom version1.11.0-2ubuntu2to1.11.0-2ubuntu2.2
- Updated libx11-devfrom version2:1.7.5-1ubuntu0.2to2:1.7.5-1ubuntu0.3
- Updated libxpm-devfrom version1:3.5.12-1ubuntu0.22.04.1to1:3.5.12-1ubuntu0.22.04.2